4 ms·
It doesn't do that. It rewrites the source address that outbound connections appear to come from; it doesn't implement any kind of access control. Take two net
by Dagger2 2y ago
It doesn't do that. It rewrites the source address that outbound connections appear to come from; it doesn't implement any kind of access control.
Take two networks that are identical, except one is doing NAT and one isn't, and test them. Every connection that works on the without-NAT network will also work on the with-NAT network. The only difference you'll find is that some outbound connections which didn't work on the former will work on the latter.
Some would argue that "every connection that used to work still works, and some connections that didn't work before do now work" is kind of the opposite of a firewall.
- cyberax 2y ago> It doesn't do that. It rewrites the source address that outbound connections appear to come from; it doesn't implement any kind of access control. It absolutely does. There is no way with NAT to connect from the outside network to the inside ("but what if the attacker is directly attached to the next hop blahblahblah"). That's all that firewalls need to do, everything else is useless noise in the current world. > Take two networks that are identical, except one is doing NAT and one isn't, and test them. Here's my IP: 192.168.80.36. Feel free to attack me. Go on. The public IPv4 of my router is 76.191.126.81. I even opened a port 8871 for you with a static page with a Bitcoin wallet worth $1000, you just need to get to it. You can't. There's no way to get to my computer without hacking the NAT server first. That's why NAT _is_ a firewall, and a foolproof one at that. It's secure by default, unlike IPv6 firewalls that can fail open.
- growse 2y agoI've just remembered the firewall alignment chart, which asserts a view of the world that an excavator is a firewall. https://sh.itjust.works/pictrs/image/421c9549-83ee-487a-9fa0-1df7368a748c.jpeg?format=webp https://sh.itjust.works/pictrs/image/421c9549-83ee-487a-9fa0...
- Dagger2 2y agoIt's possible to get to your computer without hacking the "NAT server", but I'm not in a position to do it. There's no point setting up a demonstration if you don't make it possible for me to actually do the demonstration! When I set one up for you (back here: https://news.ycombinator.com/item?id=39173556 https://news.ycombinator.com/item?id=39173556) I gave you the access needed to actually do the test (...but you either missed that message or opted to ignore it, so you never tried it). You need to either move your network to routed IPs or give me a tunnel to the upstream network of your router first. Not doing either of those doesn't make you right. NAT is still not acting as a firewall here. I'm just not in a position to take advantage of that, due to your use of RFC1918 addresses on the LAN side.
- cyberax 2y ago> It's possible to get to your computer without hacking the "NAT server", but I'm not in a position to do it. Nope. Even with a misconfigured box that forwards the traffic from WAN to LAN, you need to be in the direct contact with the NAT server (an OpenWRT box). And that's the point, you are _not_, as is pretty much everybody else in the world, outside of people who have keys to my house and my ISP. In practice, this provides all the practical security you need from a firewall. > I'm just not in a position to take advantage of that, due to your use of RFC1918 addresses on the LAN side. Well, duh. That's the whole point of NAT (when used typically). You don't get to access my internal network, you simply can't do that physically.
- Dagger2 2y agoNo, you don't need to be in direct contact with the NATing router. That's kind of the entire point we're trying to making here. All you need to be able to do is send a packet that ends up at your router with the dest IP set to one of your LAN machines. This only requires being directly attached to your router if you're using RFC1918 on the LAN; if you're using a properly routed prefix then it can be done from anywhere. > Even with a misconfigured box that forwards the traffic from WAN to LAN Forwarding traffic from WAN to LAN isn't a misconfiguration. Your router needs to do that for TCP to work, or get replies to outbound UDP.
- cyberax 2y ago> No, you don't need to be in direct contact with the NATing router. Or control the internal network of my ISP. > All you need to be able to do is send a packet that ends up at your router with the dest IP set to one of your LAN machines. Which you can't do. > if you're using a properly routed prefix then it can be done from anywhere. If I had a publically routed /24, then I wouldn't be using NAT in the first place. Which is the case in point: NAT _is_ a firewall. > Forwarding traffic from WAN to LAN isn't a misconfiguration Sigh. I mean allowing the SYN packets to be forwarded from WAN to LAN.
- 2y ago